216.73.217.22

CVE-2026-49200

· Published 29/05/2026 09:16 · Modified 29/05/2026 14:46

Labels: CVE-2026-49200 2026-05-298fc372e3-d9c5-46e4-9410-38469745c639CVE-2026-49200CWE-532

Essential information

Published
29/05/2026 09:16
Modified
29/05/2026 14:46
Author
Creator
CVSS
10.0 CRITICAL (v3) 10.0 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

The acer_cgi.log file in the device firmware is accessible without authentication via the web interface. This file contains cleartext login credentials (for web and Telnet), leading to unauthorized system access.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
8fc372e3-d9c5-46e4-9410-38469745c639
NVD
View on NVD

Affected products (CPE)

ProductCPE
acer / device firmware cpe:2.3:a:acer:device_firmware:*:*:*:*:*:*:*:*

References